The _claimYield function in AaveDIVAWrapperCore.sol does not track principal over time, allowing the owner to repeatedly claim the same yield.
Location: AaveDIVAWrapperCore.sol
Code:
Issue: Yield is calculated as aTokenBalance - wTokenSupply, which does not account for previously claimed yield.
Critical: The owner can repeatedly claim the same yield, draining funds from the contract.
Manual code review.
Track principal per collateral token:
The contest is live. Earn rewards by submitting a finding.
This is your time to appeal against judgements on your submissions.
Appeals are being carefully reviewed by our judges.